Better options than vendor-managed Docker security images?
vendor handles the scanning part of our docker security stack. every week their own components show new CVEs in the scanner image.
we open tickets, they either get marked low priority or sit without response. last real reply was weeks ago.
compliance doesn’t care where it comes from. scan fails, audit flags it, and it lands on us.
we tried pushing contract clauses around secure delivery and patch timelines, but once it’s upstream OSS inside their image, everything slows down.
right now we’re logging formal risk acceptances with compensating controls just to stay audit compliant. documented, signed, reviewed.
starting to feel like the bigger issue is relying on vendor-bundled images we don’t control.
has anyone managed to get vendors to move on this, or did you reduce dependency on their images?